Document Title: =============== SamenBlog Weblog Service - Cross Site Request Forgery / Cross Site Scripting References (Source): ==================== http://ehsansec.ir/advisories/samenblog-xsrf-xss.txt Release Date: ============= 2016-02-20 Product & Service Introduction: =============================== Samenblog allows its users to publish their information, memories, essays, etc to experience and enjoy a professional weblog-publishing system in a basic environment and also it has tried to provide a system for both professional and amateur users. Vulnerability Type: ========================= Cross Site Request Forgery Cross Site Scripting Vulnerability Details: ============================== I discovered a client-side cross site request forgery web vulnerability and a cross site scripting vulnerability in Samenblog.com (Weblog Service). Author: ================= Ehsan Hosseini http://ehsansec.ir/ Exploitation Technique: ======================= Remote Severity Level: =============== Medium Proof of Concept (PoC): ======================= -- Cross Site Request Forgery -- -- PoC : Edit Themes -- -- PoC 1 --